Skip to content
This repository has been archived by the owner on May 5, 2024. It is now read-only.

build: Add Dependency Review Action #32

Merged
merged 1 commit into from
Sep 18, 2022
Merged

build: Add Dependency Review Action #32

merged 1 commit into from
Sep 18, 2022

Conversation

joschi
Copy link
Owner

@joschi joschi commented Sep 18, 2022

This Action will scan dependency manifest files that change as part of a Pull Request, surfacing known-vulnerable versions of the packages declared or updated in the PR. Once installed, if the workflow run is marked as required, PRs introducing known-vulnerable packages will be blocked from merging.

This Action will scan dependency manifest files that change as part of a Pull Request, surfacing known-vulnerable versions of the packages declared or updated in the PR. Once installed, if the workflow run is marked as required, PRs introducing known-vulnerable packages will be blocked from merging.

- Source repository: https://github.com/actions/dependency-review-action
- Public documentation: https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review#dependency-review-enforcement
@joschi joschi added the github_actions Pull requests that update GitHub Actions code label Sep 18, 2022
@joschi joschi self-assigned this Sep 18, 2022
@joschi joschi merged commit f974e6b into main Sep 18, 2022
@joschi joschi deleted the dependency-review branch September 18, 2022 20:43
@joschi joschi added this to the 0.2.16 milestone Oct 19, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
github_actions Pull requests that update GitHub Actions code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant